๐ซ๐ท
dynamix
2026-10-09 18:13:59
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
helios.live
2026-10-09 17:09:48
(1 day ago)
2026/10/09 17:09:46 [error] 169931#169931: *356181 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/10/09 17:09:46 [error] 169931#169931: *356181 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 18.223.20.158, server: kocerroxy.com, request: "GET /wp-includes/fonts/install.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
18.223.20.158 - - [09/Oct/2026:17:09:46 +0000] "GET /wp-includes/fonts/install.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/10/09 17:09:46 [error] 169931#169931: *356181 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 18.223.20.158, server: kocerroxy.com, request: "GET /edit.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
18.223.20.158 - - [09/Oct/2026:17:09:46 +0000] "GET /edit.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 10.0; W
...
show less
Web App Attack
๐ซ๐ฎ
YF
2026-10-09 17:00:35
(1 day ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 16:32:35
(1 day ago)
445 requests with url.path */.well-known/acme-challenge/*.php
295 requests with url.path *config.p ...
show more
445 requests with url.path */.well-known/acme-challenge/*.php
295 requests with url.path *config.php
239 requests with url.path */.well-known/pki-validation/*.php
142 requests with url.path */wp.php
134 requests with url.path */wp-activate.php
130 requests with url.path */wp-sigunq.php
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
maxpower
2026-10-09 16:30:46
(1 day ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 18.223.20.158 (US/United States/ec2-18-223-20- ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 18.223.20.158 (US/United States/ec2-18-223-20-158.us-east-2.compute.amazonaws.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/10/09 18:30:38 [error] 1529675#1529675: *2015180 access forbidden by rule, client: 18.223.20.158, server: spazioitaliaarteinmovimento.it, request: "GET /wp-includes/fonts/install.php HTTP/2.0", host: "spazioitaliaarteinmovimento.it"
2026/10/09 18:30:38 [error] 1529675#1529675: *2015180 access forbidden by rule, client: 18.223.20.158, server: spazioitaliaarteinmovimento.it, request: "GET /wp-includes/images/about.php HTTP/2.0", host: "spazioitaliaarteinmovimento.it"
2026/10/09 18:30:40 [error] 1529675#1529675: *2015180 access forbidden by rule, client: 18.223.20.158, server: spazioitaliaarteinmovimento.it, request: "GET /wp-content/uploads/json.php HTTP/2.0", host: "spazioitaliaarteinmovimento.it"
show less
Port Scan
๐ฉ๐ช
Blexyel
2026-10-09 15:07:46
(1 day ago)
18.223.20.158 - - [09/Oct/2026:17:07:45 +0200] "GET /wp-includes/images/smilies/wp-login.php HTTP/1. ...
show more
18.223.20.158 - - [09/Oct/2026:17:07:45 +0200] "GET /wp-includes/images/smilies/wp-login.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ท
setupgr
2026-10-09 13:36:21
(1 day ago)
(mod_security) mod_security (id:1000001) triggered by 18.223.20.158 (US/United States/Ohio/Columbus/ ...
show more
(mod_security) mod_security (id:1000001) triggered by 18.223.20.158 (US/United States/Ohio/Columbus/-/[AS16509 Amazon.com, Inc.]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:36:16.573094 2026] [security2:error] [pid 655393:tid 655471] [remote 18.223.20.158:58433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/about.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-includes/images/about.php"] [severity "CRITICAL"] [tag "security"] [hostname "cpanagiotou.gr"] [uri "/wp-includes/images/about.php"] [unique_id "asjt0FhGuVqQpwdj1w-AfwADUhc"]
show less
Port Scan
๐ฌ๐ง
consul.to
2026-10-09 13:26:02
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-10-09 13:11:03
(2 days ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ฉ๐ช
ardexter
2026-10-09 11:41:20
(2 days ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
Anonymous
2026-10-09 10:55:02
(2 days ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-10-09 10:54:12
(2 days ago)
IP matched detection query Detection of too many failed responses.
Brute-Force
Bad Web Bot
Hacking
๐ฎ๐น
VHosting
2026-10-09 10:00:06
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
j-tap
2026-10-09 08:25:57
(2 days ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐ฉ๐ช
ramazan
2026-10-09 08:20:19
(2 days ago)
Fail2Ban: nginx-4xx | Failures: 19 | Log: /alfanew.php /berlin.php /cgi-bin/upfile.php /wp-admin/ima ...
show more
Fail2Ban: nginx-4xx | Failures: 19 | Log: /alfanew.php /berlin.php /cgi-bin/upfile.php /wp-admin/images/index.php /wp-admin/network/index.php
show less
Web App Attack
Hacking